Unfortunately not. The traffic would be encrypted to the CSS. ARPT cookies can only be inserted in clear text.
You would need to implement cookies on the server or use an ssl module offloader installed in the chassis (or external). The offloader would decrypt the ssl request and hit another content rule in clear text. That rule could use arrowpoint-cookies as a sticky method.
Thanks Dave. I have another question. When I want to take a server out of rotation for maint I assign a weight of zero to the content. The only problem is that I am balancing using sticky source ip and I cant really tell the number of remaing connections using sh service summary. The connections vary from 0 to a few. I think I am having the limitation of mega proxy using sticky source ip. Is there any way I can really tell if everybody is off the server and I can safely suspend the service.
The current connections listed under show service summary should be correct. If you are at zero, then all connections are gone.
Since you're using flow-timeout-mult, flows may stay around if not gracefully closed. Once you're at zero, suspend the service. If you don't, new connections can still be sent to the "zero weight" service, if the client is in the sticky table.
If a proxy is always sending connections and you're using sticky-ip, the entry will never age out (which maybe what you're seeing). Use sticky-inact to more agressively age out entries. Be careful w/ this command. If your sticky table becomes full, new connections will be rejected until the old entries age out.
VMware Trunk Port Group is supported from ACI version 2.1
VMM integration must be configured properly
ASA device package must be uploaded to APIC
ASAv version must be compatible with ACI and device package version
In the Previous articles of ACI Automation, we are using Postman/Newman as the Rest API tool to automate the ACI Configuration.
In this article I’m going to discuss on usin...
One of the first steps in building your ACI Fabric is to go through Fabric Discovery. While Fabric Discovery is usually a straightforward process, there are various issues that may prevent you from discovering an ACI switch. This article wil...